CEF:0|trellix|hx|9.9.0|Trellix Acquisition Started|Trellix Acquisition Started|0|rt=Feb 05 2019 17:02:11 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186 dmac=00-50-56-01-cb-25 dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS cs6=Windows 10 Enterprise 17763 externalId=1 cs3Label=Script Name cs3=Timestamped Triage deviceCustomDate2Label=Triage Request Timestamp deviceCustomDate2=Feb 05 2019 17:00:22 UTC categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/Create act=Acquisition Status msg=Host WIN11b1f2d1fea1 Timestamped Triage started categoryTupleDescription=A Host Acquisition was successfully started.
The information listed for the deviceCustomDate2Label and deviceCustomDate2 tags is only provided for triage acquisitions. The information listed for the fname and filePath tags is only provided for file acquisitions.